Authorization bypass through user-controlled key in Kibana - CVE-2026-72666
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and execute unauthorized queries on managed hosts.
The vulnerability exists due to authorization bypass through user-controlled key in Kibana Osquery live query functionality when handling requests to run live queries across Kibana spaces. A remote user can send a crafted request to execute queries against Elastic Agents assigned to a space the user cannot access to disclose sensitive information and execute unauthorized queries on managed hosts.
Exploitation requires the ability to run Osquery live queries in at least one Kibana space.